ISO/IEC 42001:2023 is, in ISO’s own words, the world’s first AI management system standard. It does not set rules for algorithms. It sets requirements for the organization that builds, buys or deploys them: who owns each AI system, what risks were assessed before it went live, what evidence exists that the controls work, and what happens when the model changes. An organization is certified against it. A person is not.
That last distinction catches most people. A job advert that asks for “ISO 42001 certification” is asking about a person, and the only thing a person can hold is a training credential. A procurement questionnaire that asks for it is asking about your organization, and what it means is the audit. This page explains what the standard requires, then points you to whichever part of it you need.
What an AI management system is
An AI management system, or AIMS, is the set of policies, roles, processes and records an organization uses to keep its AI under control. It is a way of working, not a piece of software.
The standard’s own scope statement is precise about what it does: it “specifies the requirements and provides guidance for establishing, implementing, maintaining and continually improving an AI management system within the context of an organization.” Requirements and guidance, in one document.
ISO 42001 uses the harmonized structure shared across ISO management system standards, so an organization running a working information security management system already has much of the scaffolding: a scope, a policy, a risk method, an internal audit function, a management review cycle. The standard adds obligations specific to AI on top of that frame.
If you want the AIMS itself rather than the standard around it, start with what an AIMS is.
How the standard is structured
ISO/IEC 42001 is a 51-page document. Clauses 1 to 3 cover scope, references and terms; clauses 4 to 10 carry the requirements; four annexes follow.
| Clause | What it requires |
| 4 Context of the organization | Determine the scope: which entities, products and AI systems sit inside the AIMS |
| 5 Leadership | An AI policy approved by top management, with defined roles, responsibilities and authorities |
| 6 Planning | AI risk assessment, AI risk treatment, AI system impact assessment, objectives, planning of changes |
| 7 Support | Resources, competence, awareness, communication, documented information |
| 8 Operation | Operational planning and control, plus risk assessment, risk treatment and impact assessment in operation |
| 9 Performance evaluation | Monitoring and measurement, internal audit, management review |
| 10 Improvement | Continual improvement, nonconformity and corrective action |
One detail that trips people copying an ISO 9001 template: in ISO/IEC 42001 clause 10 runs continual improvement first and nonconformity second, which is the reverse of 9001’s ordering.
What is in Annex A, and what we will not tell you
Annex A of ISO/IEC 42001 is where the AI specificity lives. It is normative, it runs four pages, and it is titled “Reference control objectives and controls”. Annex B, “Implementation guidance for AI controls”, runs from page 21 to page 45 and is also normative, meaning it is an integral part of the standard rather than optional background reading. Annexes C and D are informative.
The controls are grouped into nine categories:
- Policies related to AI
- Internal organization
- Resources for AI systems
- Assessing impacts of AI systems
- AI system life cycle
- Data for AI systems
- Information for interested parties
- Use of AI systems
- Third-party and customer relationships
We do not publish a control count. A specific number circulates widely in vendor blogs and conference talks. We checked ISO’s catalogue page, ISO’s two explainer pages, the official preview of the standard and the preview of ISO/IEC 42006:2025. None of them states a count, and the Annex A table is not enumerated in any free source. The number in circulation traces back to implementers reading the purchased standard, not to ISO. If the exact control set matters to your project, buy the standard.
One honest caveat on the nine categories above. They are confirmed from ISO’s final draft of the standard and from the structure of Annex B, which maps one to one against Annex A. The published Annex A table itself sits behind the paywall, so treat the wording as accurate rather than as a verbatim quotation.
What the controls cover, and how to select the ones that apply to you, is in ISO 42001 Annex A controls.
Does the standard use a Plan Do Check Act cycle?
Yes and no, and the difference is worth knowing if you are writing internal documentation that has to survive an auditor reading it.
ISO’s own website describes ISO/IEC 42001 as “built around a ‘Plan-Do-Check-Act’ process”. The standard’s text does not. It says instead that it “applies the harmonized structure (identical clause numbers, clause titles, text and common terms and core definitions) developed to enhance alignment among management system standards”. PDCA is a fair description of what that structure produces, with clause 6 as the plan, clause 8 the do, clause 9 the check and clause 10 the act. It is not language the standard uses about itself.
Either way, the point holds: the certificate covers a system that is supposed to keep running, not a project that finished.
Does it apply to you, and in what role?
ISO/IEC 42001 is technology-neutral. A retrieval system built on internal documents and a foundation model reached through an API fall under the same discipline. What changes your obligations is not the model. It is the role your organization holds in relation to the AI system: whether you develop it, provide it, or use it.
Getting that role wrong at the start is the most expensive mistake in a first implementation, because the wrong role produces the wrong scope, and the wrong scope produces a year of the wrong artifacts.
What certification involves
ISO does not certify anyone. In its own words: “ISO does not perform certification or issue certificates.” Certification is carried out by independent certification bodies, and those bodies are themselves assessed against ISO/IEC 17021-1:2015 and, for AI management systems specifically, against ISO/IEC 42006:2025, which sets requirements for bodies providing audit and certification of artificial intelligence management systems.
The audit runs in two stages: a Stage 1 review of documentation and readiness, then a Stage 2 audit that tests whether the management system is actually running. Certificates are typically issued on a three-year cycle, with surveillance audits at least annually and a recertification audit before expiry. ISO/IEC 17021-1 allows a scheme to set a different cycle, so treat three years as the norm rather than a rule.
The time is rarely in the audit. It is in the management system reaching the point where it has generated real evidence: risks treated, impact assessments completed, at least one internal audit, at least one management review. An audit of a system that has been running for three weeks finds a system that has been running for three weeks.
How the two stages differ is covered in the Stage 1 and Stage 2 audit. What the management system takes to build is in ISO 42001 implementation.
What a certificate does and does not prove
An ISO/IEC 42001 certificate proves that an independent auditor found a management system operating against the requirements of the standard, within a defined scope, on the dates of the audit.
It does not prove that a particular model is safe, accurate or unbiased. It does not certify individual people. It does not cover AI systems outside the stated scope, which is why reading the scope statement on someone’s certificate matters more than seeing that they have one.
This is where the market’s scepticism is best aimed. “Is this just a paper exercise?” is a fair question, and the honest answer is that it can be. Three things separate a real implementation from a cosmetic one, and all three are visible to a buyer who asks:
- The AI inventory is current. Real programs have a defined way of capturing new AI systems, including AI arriving inside SaaS tools nobody procured as AI.
- Impact assessments name specific harms with named owners. “Bias” is a category. A measured differential error rate across a protected class, with an owner and a review date, is a risk.
- The internal audit finds things. An internal audit reporting zero issues year after year is evidence about the audit function, not about the management system.
Where does ISO 42001 sit next to NIST and the EU AI Act?
ISO 42001, the NIST AI RMF, the EU AI Act and ISO/IEC 42005 are four different categories of instrument, and comparing them as rivals is the fastest way to misread all four.
| Instrument | Type | Certifiable |
| ISO/IEC 42001:2023 | Management system standard | Yes, by an independent certification body |
| NIST AI RMF (AI 100-1) | Voluntary framework | No. NIST describes it as voluntary and defines no certification scheme |
| EU AI Act, Regulation (EU) 2024/1689 | Binding regulation | Conformity assessment for high-risk systems, not for management systems |
| ISO/IEC 42005:2025 | Guidance standard | No. It supports the impact assessment that 42001 requires |
Two dates are worth getting right, because they moved and a great deal of published material still carries the old ones. The EU AI Act’s high-risk obligations were postponed by Regulation (EU) 2026/1744: Annex III high-risk systems now apply from 2 December 2027, and Annex I from 2 August 2028.
And in Colorado, the original AI Act that named ISO/IEC 42001 and the NIST AI RMF as the basis of an affirmative defense was repealed and reenacted by SB 26-189, signed 14 May 2026 and applying from 1 January 2027. The replacement is a disclosure and consumer-rights regime. The reasonable-care duty, the rebuttable presumption and the named recognition of ISO 42001 are all gone from the statute.
If anyone tells you that certifying to ISO 42001 buys you a statutory defense in Colorado, they are describing a law that no longer exists. The case for the standard rests on procurement, evidence and operating discipline, which is where it was always strongest.
The full picture is in ISO 42001 compared with ISO 27001.
What the standard actually fixes
Four operating problems, described by the symptom rather than the principle.
The vendor questionnaire. A long AI security and ethics questionnaire arrives from an enterprise buyer, the team spends weeks assembling answers from scratch, and a competitor answers the same question in one line. A management system does not make the questionnaire go away. It means the answers already exist as evidence.
Shadow AI. A team stands up a customer-facing assistant with a tool nobody reviewed, and it surfaces months later. The standard does not stop this. It forces “what AI do we run?” to be a question with a maintained answer.
Board accountability. The audit committee asks what the AI risk is and receives a deck of definitions instead of a register. Clause 5 and clause 6 produce the artifact the committee already knows how to read.
The model-change blind spot. A supplier updates the underlying model and quality moves before anyone notices. Life cycle and third-party controls turn that from a back-channel conversation into a documented trigger.
Each of these is a scoping and evidence problem before it is a technology problem, which is why the standard is written the way it is.
Where to go next
| If you need | Go to |
| What an AI management system is | what an AIMS is |
| The controls and how to select them | ISO 42001 Annex A controls |
| How to build the system, and how it fails | ISO 42001 implementation |
| The risk and impact assessment requirements | ISO 42001 clause 6 risk requirements |
| Which documents you have to produce | ISO 42001 mandatory documents |
| Which related standard covers what | the ISO/IEC 42000 standards family |
| How it compares with ISO 27001 and the frameworks | ISO 42001 compared with ISO 27001 |
| Training for the people who will run it | GAICC’s ISO/IEC 42001 courses |
Frequently Asked Questions
Is ISO 42001 mandatory in the United States?
No. It is a voluntary standard and no US federal law requires it. Some state AI laws reference recognized risk management frameworks, but Colorado’s named recognition of ISO 42001 was repealed in May 2026, so check the current text of any law before relying on it. The practical pressure in the US market comes from enterprise procurement, not statute.
How is ISO 42001 different from the NIST AI RMF?
The NIST AI RMF is voluntary by design and defines no certification scheme. ISO/IEC 42001 is a management system standard that an independent body audits and certifies, with ISO/IEC 17021-1 and ISO/IEC 42006:2025 governing how those bodies operate. Organizations commonly use the RMF as the reference model and the standard as the system that produces evidence.
Can we align with the standard without certifying?
Yes. Alignment captures most of the operating benefit. Certification adds the external audit and the certificate, which is what procurement teams ask for. Many organizations align for a cycle or two first.
Who should own it internally?
Most US programs sit with the CISO, the Chief Risk Officer, or a designated AI governance lead. Clause 5 requires leadership commitment, so whoever owns it needs real executive sponsorship. Day to day it is usually a small core team pulling in legal, data science, security, privacy and product.
What is ISO/IEC 42005 and do we need it?
ISO/IEC 42005:2025 is guidance on AI system impact assessment. ISO/IEC 42001 requires the assessment; 42005 describes how to do it. Certification is to 42001. Note that 42005 is often confused with ISO/IEC 42006:2025, which sets requirements for the bodies that certify management systems, not for you.
How many controls are in Annex A?
We will not print a number, because no free official source publishes one. Annex A is normative and runs four pages, grouped into the nine categories listed above. Any specific count you see online comes from someone reading the purchased standard, not from ISO.
Does the certificate cover our whole company?
Only what the scope statement says. Scopes are frequently narrower than the certificate implies, covering one product line or one legal entity. When you are assessing someone else’s certificate, read the scope.
